BleepingComputer.com: trojan dropper win32/sirefef.b , no internet connection

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

trojan dropper win32/sirefef.b , no internet connection firewall wont turn on, RPC locater stopped wont start.

#1 User is offline   cobalt5002 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 27
  • Joined: 28-May 08
  • Gender:Male
  • Location:pittsburgh, pa

Posted 08 October 2011 - 05:08 PM

Hi, my father got a trojan dropper win32/sirefef.b virus the other day.
so far the internet connection is knocked out, it shows all 0's for ip address, in network connections the message is there, saying " connecting"
also, the windows firewall is disabled and wont enable.
Remote Procedure Call,RPC, locator is stopped in services and wont restart.

ok, some new info here so i will edit in.
i did a r-click on my computer, then manage, services apps, then services, found the RPC locator disabled, so i set to automatic and started, it did fine. rebooted, but still find the following problems:

however, DHCP client was on auto but wont start. when i try to start i get
error 1075, the dependency service does not exist or is marked for deletion.
windows firewall/internet connection sharing is on auto but wont start. when i try to start i get
error 10050 socket operation encountered dead network.

would the windows repair feature on a windows install disk get it back up and running?
or is it time to reinstall?

question? i found in the services, something called "remote registry" which allows a remote user to alter the registry, how convenient. it was set to automatic. i set it to disable. not sure if that is the first thing a hacker would change if trying to gain access. am i correct that it should be set to disable unless you have a bonified remote assist in progress?

This post has been edited by cobalt5002: 08 October 2011 - 06:35 PM


#2 User is offline   cobalt5002 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 27
  • Joined: 28-May 08
  • Gender:Male
  • Location:pittsburgh, pa

Posted 08 October 2011 - 10:07 PM

can i have some help, please?

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users